CVE-2026-42291 Details
Description
SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoints for reading and creating sharing links for personal notes is not properly authorized. This allows authenticated attackers who obtain the note ID of victim users to list and create sharing links to those users' personal notes. This gives attackers read and write access to notes of other users. This exploit works in both SysReptor Professional and Community. In Community it has, however, no impact because all users have superuser permissions and can list personal notes of other users at /admin/pentests/usernotebookpage/. This issue has been patched in version 2026.27.
A vulnerability exists in SysReptor versions 2026.4 prior to 2026.27, allowing authenticated attackers to exploit improper authorization in the endpoints for reading and creating sharing links for personal notes. Attackers who obtain the note ID of other users can list and create sharing links to those users' personal notes, thereby gaining read and write access to those notes. This issue affects both SysReptor Professional and Community versions, although in Community, it has no impact due to all users having superuser permissions which allow access to personal notes of others.
Users can update to SysReptor version 2026.27, which addresses this vulnerability. Instructions for updating are available in the SysReptor documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Syslifters/sysreptor/releases/tag/2026.27 | [email protected] | Release NotesVendor |
| https://github.com/Syslifters/sysreptor/security/advisories/GHSA-pcpr-q2qj-3v43 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SysReptor | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | New CVE Received | [email protected] |
Volerion